CVE-2022-49866: Linux Kernel
Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: net: wwan: mhi: fix memory leak in mhi_mbim_dellink MHI driver registers network device without setting the needs_free_netdev flag, and does NOT call free_netdev() when unregisters network device, which causes a memory leak. This patch sets needs_free_netdev to true when registers network device, which makes netdev subsystem call free_netdev() automatically after unregister_netdevice().
Affected products
- Linux Linux Kernel: from 5.15, before 5.15.79 (fixed in 5.15.79); from 5.16, before 6.0.9 (fixed in 6.0.9); version 6.1 only
Published 2025-05-01. Last modified 2026-06-17.